mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-29 19:30:11 +00:00
nixos/wrappers: enforce target executable is ELF
This *will* break some things, such as `nixosTests.espanso`. This is intended: Loading bash, python or perl scripts via SUID or extensive capabilities is dangerous. PERL5LIB, PYTHONPATH or BASH_ENV make these things trivial LPE primitives. The mime types being matched include both static, non-static and pie ELFs. This should be fine until we somehow get yet another type of magic and associated mime type.
This commit is contained in:
@@ -361,16 +361,19 @@ in
|
||||
|
||||
###### wrappers consistency checks
|
||||
system.checks = lib.singleton (
|
||||
pkgs.runCommandLocal "ensure-all-wrappers-paths-exist"
|
||||
pkgs.runCommandLocal "ensure-wrapper-integrity"
|
||||
{
|
||||
nativeBuildInputs = [ pkgs.libcap-text-verifier ];
|
||||
nativeBuildInputs = [
|
||||
pkgs.libcap-text-verifier
|
||||
pkgs.file
|
||||
];
|
||||
preferLocalBuild = true;
|
||||
}
|
||||
''
|
||||
# make sure we produce output
|
||||
mkdir -p $out
|
||||
|
||||
echo -n "Checking that Nix store paths of all wrapped programs exist... "
|
||||
echo -n "Checking that Nix store paths of all wrapped programs exist and are ELF executables... "
|
||||
${lib.toShellVar "wrappers" (lib.mapAttrs (n: v: v.source) wrappers)}
|
||||
for name in "''${!wrappers[@]}"; do
|
||||
path="''${wrappers[$name]}"
|
||||
@@ -382,6 +385,15 @@ in
|
||||
test -t 1 && echo -ne '\033[0m'
|
||||
exit 1
|
||||
fi
|
||||
magic=$(file --mime --brief --dereference "$path")
|
||||
if ! [[ "$magic" =~ application/x-executable || "$magic" =~ application/x-pie-executable ]]; then
|
||||
test -t 1 && echo -ne '\033[1;31m'
|
||||
echo "FAIL"
|
||||
echo "The target executable $path is not an ELF! This is a security risk."
|
||||
echo "Script wrappers (e.g. bash or python) are commonly susceptible to dangerous env var injections."
|
||||
test -t 1 && echo -ne '\033[0m'
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
echo "OK"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user